Comment 42 for bug 1546507

Revision history for this message
Nikhil Komawar (nikhil-komawar) wrote : Re: Regular user can delete any image file

Thanks for the clarification Mike. This really helps.

I browsed through the patch, I do have a question regarding the direct snapshot method in Nova for RBD pool. I think with this change they will need to enable the unrestricted location access, which I think we can avoid by adding a logic in the policy check that identifies if a http url or image_id or the rbd style "snap" is present in the location url. Also, it would be nice to have a note above that logic explaining why only these are being considered in the if case.

Make sense?